As reported by SecurityAffairs, CISA has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, all linked to a broader espionage campaign attributed to China-based Integrity Technology Group. A joint advisory from seven nations accompanies the update, and the DOJ has seized two tools — Microscan and FishHub — allegedly used to scan for vulnerable systems and facilitate spear-phishing operations.
The most striking takeaway isn't the sophistication of the exploitation. It's the age of the flaws. CVE-2015-3306 and CVE-2015-5477 have been public knowledge for over eleven years. Their continued presence in exploitable deployments suggests that legacy infrastructure — FTP servers, DNS resolvers, outdated application frameworks — remains critically undermanaged in many organizations.
KEV Additions at a Glance
| CVE | Product | CVSS | Severity | Flaw Type | Exploited |
|---|---|---|---|---|---|
| CVE-2015-3306 | ProFTPD | 10.0 | Critical | Access control bypass (SITE CPFR/CPTO) | Yes — in the wild |
| CVE-2021-3199 | ONLYOFFICE Docs | 9.8 | Critical | Path traversal with JWT enabled | Yes — in the wild |
| CVE-2016-3081 | Apache Struts | 8.1 | High | Command injection (DMI enabled) | Yes — in the wild |
| CVE-2023-22894 | Strapi | 7.2 | High | Cleartext sensitive data exposure | Yes — in the wild |
| CVE-2015-5477 | ISC BIND | 7.5 | High | DoS via TKEY query assertion | Yes — in the wild |
Why This Matters
Three of these five vulnerabilities are old enough to predate modern vulnerability management programs. The fact that nation-state actors are still finding exploitable instances tells us two things: first, that scanning tools like the seized Microscan are effective at finding unpatched edge devices and services exposed to the internet; second, that many organizations lack visibility into their external attack surface and cannot answer the simple question, do we even run ProFTPD or an older BIND resolver?
The ONLYOFFICE Docs vulnerability (CVE-2021-3199) deserves particular attention. Document collaboration platforms are increasingly internet-facing, and a 9.8 CVSS path traversal that enables remote code execution when JWT is enabled is a dangerous combination. Many SaaS-adjacent deployments may not even realize they're running a vulnerable version.
Broader Implications
Shield53 Recommendations
Immediate Actions
- Inventory and patch all five CVEs within the CISA KEV remediation window (typically 14 days for federal agencies; all organizations should treat as urgent).
- ProFTPD (CVE-2015-3306): Upgrade to version 1.3.6c or later. If upgrade is impossible, disable the SITE CPFR/SITE CPTO commands or restrict access via
Limitdirectives in the ProFTPD configuration. Check for signs of prior compromise — unauthorized file modifications, unusual SFTP sessions. - ONLYOFFICE Docs (CVE-2021-3199): Update to a patched version. Audit JWT configuration and review upload directories for unexpected files indicating prior traversal exploitation.
- Apache Struts (CVE-2016-3081): Upgrade to Struts 2.3.20.3 or 2.5.x or later. Ensure Dynamic Method Invocation is disabled (it's off by default in modern versions — verify your config hasn't re-enabled it).
- Strapi (CVE-2023-22894): Upgrade to a patched version. Rotate any credentials or secrets that may have been exposed in cleartext. Review admin panel access logs for suspicious query patterns.
- ISC BIND (CVE-2015-5477): Update to BIND 9.10.3-P2 or later. Restrict TKEY queries to trusted hosts only. Monitor resolver availability for unexpected restarts or crashes.
Detection & Hunting
- Search perimeter logs and SIEM for the following indicators: ProFTPD
SITE CPFR/SITE CPTOcommand sequences; BIND resolver crash events correlated with TKEY queries; Apache Struts requests containingmethod:prefixes; Strapi admin API calls with unusual query filter parameters. - Review external-facing services for exposure of ONLYOFFICE, Strapi admin panels, ProFTPD, and BIND resolvers. If these services don't need to be internet-facing, move them behind a VPN or zero-trust gateway immediately.
- Hunt for post-exploitation artifacts: credential dumps, email exfiltration, unusual VPN sessions — all consistent with the described campaign's tactics.
The real lesson here isn't that adversaries are using old vulnerabilities — it's that we keep letting them work. If your organization can't produce a credible inventory of internet-facing services within hours, you're operating at a disadvantage that no SOC tool can fix.